Courseiva
Describe the capabilities of Microsoft EntrahardMultiple ChoiceObjective-mapped

Conditional Access Sign-in Frequency Session Control

A company uses Microsoft Entra ID. They have a critical application that requires additional security. The security team wants to enforce multifactor authentication (MFA) for every access to the application, but they also want users to reauthenticate with MFA if a session lasts longer than 60 minutes, regardless of device compliance. Which Conditional Access control should the administrator configure?

Quick Answer

The key distinction this question is testing is grant controls versus session controls within Conditional Access — two different categories of setting that are easy to conflate. Grant controls decide whether access is allowed at all at the moment of sign-in, which is where a blanket 'require MFA' requirement lives, but a grant control only fires once per session and has nothing to say about what happens later in that same session. Sign-in frequency is a session control, and it operates on a completely different axis: it forces the user to reauthenticate, MFA included, once a session has been active longer than a defined interval — 60 minutes in this scenario — regardless of whether the device remains compliant or the original sign-in was already fully authenticated. That's precisely why device compliance doesn't factor into the answer here: sign-in frequency is a time-based trigger, not a device-state check, so it keeps re-prompting on schedule even for a device that never stops being compliant. Any scenario describing a maximum session duration or a mandate to periodically re-verify identity during a long-lived session, rather than a one-time access decision, is pointing at sign-in frequency specifically.

⚠ Common exam trap

Watch out — candidates often confuse 'Grant controls' (which enforce conditions at sign-in) with 'Session controls' (which manage behavior after sign-in), leading them to select 'Require multifactor authentication' instead of 'Sign-in frequency' for time-based reauthentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Session control: Sign-in frequency

The requirement to force reauthentication with MFA after a specific time period (60 minutes) is a session-level control, not a grant control. The 'Sign-in frequency' session control in Conditional Access allows administrators to define how often a user must reauthenticate, including re-prompting for MFA, regardless of device compliance. This directly meets the scenario's need for a time-based reauthentication policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Grant control: Require multifactor authentication

    Why it's wrong here

    Grant control enforces MFA at initial sign-in, but does not control how often users are prompted to reauthenticate during an active session.

  • Session control: Sign-in frequency

    Why this is correct

    Sign-in frequency as a session control forces users to reauthenticate after a specified time period, ensuring MFA is revalidated if the session exceeds 60 minutes.

  • Session control: Application enforced restrictions

    Why it's wrong here

    Application enforced restrictions is used to require the application to enforce device compliance, not to control MFA reauthentication frequency.

  • Grant control: Require device to be marked as compliant

    Why it's wrong here

    Requiring device compliance is a grant control for initial access, not for prompting reauthentication during a session.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization uses Microsoft Entra ID and wants to require users to re-authenticate every 4 hours when accessing a critical financial application, even if the user already has an active sign-in session. Which Conditional Access control should be configured?

medium
  • A.Grant control 'Require multi-factor authentication'
  • B.Session control 'Sign-in frequency'
  • C.Session control 'Persistent browser session'
  • D.Grant control 'Require device to be marked as compliant'

Why B: The 'Sign-in frequency' session control in Conditional Access allows administrators to specify the time interval after which a user must re-authenticate, even if they have an active session. By setting this to 4 hours, the organization ensures that users re-authenticate before accessing the critical financial application, overriding any existing session tokens.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.